ID

VAR-202108-0277


CVE

CVE-2021-22397


TITLE

Huawei ManageOne  Authentication Vulnerability in Microsoft

Trust: 0.8

sources: JVNDB: JVNDB-2021-009450

DESCRIPTION

There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service. Huawei ManageOne Contains an improper authentication vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. Huawei Manageone is a set of cloud data center management solutions of China Huawei (Huawei). The product supports unified management of heterogeneous cloud resource pools, and provides functions such as multi-level VDC matching customer organization model, service catalog planning, self-service, centralized alarm analysis, and intelligent operation and maintenance

Trust: 2.34

sources: NVD: CVE-2021-22397 // JVNDB: JVNDB-2021-009450 // CNNVD: CNNVD-202104-975 // VULHUB: VHN-380832 // VULMON: CVE-2021-22397

AFFECTED PRODUCTS

vendor:huaweimodel:manageonescope:eqversion:8.0.0

Trust: 1.8

vendor:huaweimodel:manageonescope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-009450 // NVD: CVE-2021-22397

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22397
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-22397
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202104-975
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202107-1043
value: MEDIUM

Trust: 0.6

VULHUB: VHN-380832
value: MEDIUM

Trust: 0.1

VULMON: CVE-2021-22397
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22397
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-380832
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-22397
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-22397
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-380832 // VULMON: CVE-2021-22397 // JVNDB: JVNDB-2021-009450 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202107-1043 // NVD: CVE-2021-22397

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.1

problemtype:Improper authority management (CWE-269) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-380832 // JVNDB: JVNDB-2021-009450 // NVD: CVE-2021-22397

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202107-1043

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

PATCH

title:Security Advisory - Privilege Escalation Vulnerability in Huawei Productsurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210714-01-pe-en

Trust: 0.8

sources: JVNDB: JVNDB-2021-009450

EXTERNAL IDS

db:NVDid:CVE-2021-22397

Trust: 3.4

db:JVNDBid:JVNDB-2021-009450

Trust: 0.8

db:CNNVDid:CNNVD-202107-1043

Trust: 0.7

db:CS-HELPid:SB2021041363

Trust: 0.6

db:CNNVDid:CNNVD-202104-975

Trust: 0.6

db:CS-HELPid:SB2021071505

Trust: 0.6

db:VULHUBid:VHN-380832

Trust: 0.1

db:VULMONid:CVE-2021-22397

Trust: 0.1

sources: VULHUB: VHN-380832 // VULMON: CVE-2021-22397 // JVNDB: JVNDB-2021-009450 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202107-1043 // NVD: CVE-2021-22397

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210714-01-pe-en

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-22397

Trust: 1.4

url:https://www.cybersecurity-help.cz/vdb/sb2021041363

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210714-01-pe-cn

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021071505

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/269.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-380832 // VULMON: CVE-2021-22397 // JVNDB: JVNDB-2021-009450 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202107-1043 // NVD: CVE-2021-22397

CREDITS

The vulnerability was discovered by Huawei's internal testing

Trust: 0.6

sources: CNNVD: CNNVD-202107-1043

SOURCES

db:VULHUBid:VHN-380832
db:VULMONid:CVE-2021-22397
db:JVNDBid:JVNDB-2021-009450
db:CNNVDid:CNNVD-202104-975
db:CNNVDid:CNNVD-202107-1043
db:NVDid:CVE-2021-22397

LAST UPDATE DATE

2024-08-14T12:55:57.750000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-380832date:2022-07-12T00:00:00
db:VULMONid:CVE-2021-22397date:2021-08-11T00:00:00
db:JVNDBid:JVNDB-2021-009450date:2022-04-27T07:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-14T00:00:00
db:CNNVDid:CNNVD-202107-1043date:2022-07-14T00:00:00
db:NVDid:CVE-2021-22397date:2022-07-12T17:42:04.277

SOURCES RELEASE DATE

db:VULHUBid:VHN-380832date:2021-08-02T00:00:00
db:VULMONid:CVE-2021-22397date:2021-08-02T00:00:00
db:JVNDBid:JVNDB-2021-009450date:2022-04-27T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-13T00:00:00
db:CNNVDid:CNNVD-202107-1043date:2021-07-14T00:00:00
db:NVDid:CVE-2021-22397date:2021-08-02T17:15:14.130